Devising controls for information security is a balance between?
A.
Governance and compliance
B.
Auditing and security
C.
Budget and risk tolerance
D.
Threats and vulnerabilities
The Answer Is:
C
This question includes an explanation.
Explanation:
Information security controls are designed by balancing the available budget against the organization's risk tolerance. This balance ensures that the controls are both cost-effective and aligned with the organization's capacity to accept or mitigate risks. Governance and compliance (A) and auditing and security (B) pertain to regulatory and monitoring aspects, while threats and vulnerabilities (D) are inputs to risk assessments rather than direct factors in control design.